The crypto industry has long been plagued by hacking incidents and exploits, but the situation is now worsening due to the advent of artificial intelligence. According to Charles Guillemet, Chief Technology Officer at Ledger, a prominent crypto wallet provider, AI is rendering the economics of cybersecurity obsolete by making it faster and cheaper to launch attacks on systems.
Guillemet emphasized that identifying vulnerabilities and exploiting them has become extremely easy, with the cost of doing so approaching zero. His comments come at a time when crypto heists are once again making headlines, with recent incidents including the exploitation of Solana-based DeFi protocol Drift, resulting in the theft of $285 million worth of digital assets, and an attack on yield protocol Resolv, which led to $25 million in losses. Over the past year, crypto attacks have resulted in the theft or loss of over $1.4 billion in assets, according to data from DefiLlama. The traditional security paradigm, which relies on the principle that hacking a system should be more difficult and expensive than the potential reward, is being eroded by AI.
Tasks that previously required skilled researchers months to accomplish, such as reverse engineering software or chaining exploits, can now be completed in seconds using the right prompts. For crypto, where code often controls large pools of funds, this shift significantly raises the stakes.
Guillemet cautioned teams developing blockchain protocols that they need to be perfect, as even a single mistake can have severe consequences. The problem is further complicated by AI-generated code, which can spread vulnerabilities more quickly as more developers rely on AI tools. Guillemet emphasized that there is no single solution to make code secure and that a significant amount of code will be insecure by design.
To address this issue, crypto protocols need to rethink security from the ground up. Guillemet suggested that formal verification, which involves using mathematical proofs to validate code, is a more robust approach than traditional audits, which may miss bugs. He also recommended hardware-based security, such as devices that isolate private keys from internet-connected systems, reducing exposure. For average crypto users, Guillemet's message is clear: assume that systems can and will fail, and therefore, it is essential to be cautious and take additional security measures, such as using cold storage and keeping sensitive data offline.
However, even these measures are not foolproof, as risks extend beyond software to include physical attacks targeting crypto holders. Guillemet expects a divide in the future, where critical systems like wallets and protocols will invest heavily in security and adapt, while much of the broader software ecosystem may struggle to keep up, making it increasingly easier for hackers to launch successful attacks.